Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-06-18

Daily Intelligence Briefing — Thursday, June 18, 2026

2 critical14 high

On 2026-06-18, Threadlinqs published 16 new threat reports, 2 rated critical and 14 high, spanning 138 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 144 new detection rules and 391 extracted indicators.

New threats
1616 threat lines
Critical / high
162 critical · 14 high
ATT&CK techniques
138Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
391Count only · values are Red+
Detection rules
144New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow). Fake GitHub 'EQVita' Homebrew Repo Delivers SmartLoader and Lumma Stealer to the Retro Gaming / PlayStation Vita Modding Community. Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models.

Highlights

  • TL-2026-0846 — astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow)
  • TL-2026-0849 — Fake GitHub 'EQVita' Homebrew Repo Delivers SmartLoader and Lumma Stealer to the Retro Gaming / PlayStation Vita Modding Community
  • TL-2026-0850 — Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models
  • TL-2026-0851 — Roblox Developer Group Takeovers via Malicious 'robase' Python Package and Discord Job-Offer Social Engineering
  • TL-2026-0852 — International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp

Theme of the day

Active exploitation of various vulnerabilities enabled evasion, credential harvesting, and malware delivery. Threat actors targeted multiple sectors with phishing, supply-chain attacks, and unauthenticated code execution.

  • financially-motivated
  • infostealer
  • masquerading
  • social-engineering
  • credential-theft

Threats published

16 threat lines in the 2026-06-18 debrief, most severe first. Each links to its full profile.

Techniques observed

138 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

  • PolinRider
  • Water Kurita (SmartLoader operators) / Storm-2477 (Lumma developer)
  • TA569 (Mustard Tempest)
  • Icarus
  • Vo1d / Mzmess operators (Popa proxy layer linked to NetNut)
  • Versatile Werewolf
  • TA569 (SocGholish operator)

Nation-state attribution

  • North Korea
  • Russia

Threat categories

  • SUPPLY_CHAIN
  • MALWARE
  • VULNERABILITY

Severity breakdown

  • critical2
  • high14
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

391 indicators of compromise · Red and above. Compare plans
  • behavioral 133
  • network 98
  • file 81
  • infrastructure 20
  • tool 17
  • malware 16
  • entity 13
  • package 8
  • technique 5
144 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans